Reference🧭 Global overviewsIntermediate⏱ 26 min read

📅 Subscriptions and recurring payments around the world

Card mandates vs. bank mandates, MIT flagging and the chaining the schemes require, e-NACH and UPI AutoPay, PayTo and Pix Automático, one-click cancellation rules, and the economics of a declined payment

One subscription, two mandates

A subscription is the supply of goods or services in exchange for repeated payments at an agreed interval. It rests on two separate contracts, and nothing requires them to line up. The first binds the customer to the merchant and sets the term, price, notice period, and cancellation terms. The second authorizes the repeated movement of money, and is called a mandate. The mandate lives outside the terms and conditions, follows different rules, and often lapses without the commercial contract being canceled. The gap between the two explains most of the problems in recurring billing, whether debits continue after a cancellation or payments stop when the customer wanted to stay.

Two families of mandates divide the world. The card mandate comes from private rules, those of the schemes, attached to a credential stored by the merchant or its provider, and no national law defines it. The bank mandate is written into an enforceable rulebook, often backed by national law. The difference shows in the proof each one requires. The first is proved by a technical flag carried in each authorization, while the second is proved by a document the creditor must be able to produce.

Card, recurring MITSEPA Direct Debit CoreDirect Debit (Bacs)Pix Automático
Who writes the rulesThe schemes: Visa, Mastercard, domestic networksEuropean Payments CouncilPay.UKBanco Central do Brasil
Where consent livesIn a stored credential, plus a flag carried in each authorizationIn a mandate held by the creditor, who must be able to produce itIn an instruction held by the creditor, under a Service User NumberIn the payer's banking app
Can the customer stop it on their own?No. They go through the merchant, or block their cardYes, by having their bank block the mandateYes, by canceling with their bank; the creditor finds out through ADDACSYes, self-service, with immediate effect
Returns and disputesChargeback under scheme rulesNo-questions-asked refund within 8 weeks; 13 months if the mandate is disputedDirect Debit Guarantee: refund with no cap and no time limitNone. A settled payment doesn't come back
What breaks in practiceThe credential expires before the customer leavesInsufficient funds on the collection dateAdvance notice wasn't sent, and the indemnity claim is lost automaticallyThe authorization is revoked and no one tells the creditor
One monthly subscription, four payment instruments
🔑
The mandate follows the instrument, not the customer
A customer of six years can stop paying without deciding anything, because their card was reissued, their bank blocked the mandate, or their account moved to another bank. Conversely, a customer who canceled by email keeps getting debited as long as the mandate is alive. Both situations produce the same symptom in the books and call for opposite remedies. So measure the two separately: voluntary churn, which is a product and pricing matter, and involuntary churn, which comes down to payment method maintenance and the retry schedule.

This distinction drives reserves. A card program reserves for chargebacks and for attrition in its stored credentials, a SEPA program reserves for eight weeks of no-questions-asked refunds, and a UK program reserves with no end date. A Brazilian program on Pix Automático reserves for no returns at all, but must absorb instant revocation. Each instrument calls for a different kind of reserve, and applying one instrument's model to another overstates the risk in one case and understates it in the other.

Credentials on file and the chaining the schemes require

Credential-on-file means storing a payment method for future charges. Visa's Stored Credential Framework, in effect since 2017 and adopted by Mastercard, turned this commercial practice into something the scheme regulates. It defines two flags. A CIT (Customer-Initiated Transaction) assumes the cardholder is present and taking action, while an MIT (Merchant-Initiated Transaction) is triggered by the merchant alone, under a mandate obtained during an earlier CIT.

the issuer sends it backstored by the merchantInitial CIT3DS2 or zero-value + mandatenetwork transaction IDTransaction ID (Visa) · Trace ID (MC)Vaultto store and migrateMIT recurringfixed amount and dateMIT installment3 interest-free installmentsUCOFusage-based, variableResubmissionretry after 51referenced in EVERY MITMIT flagged correctlyoutside SCA scope, no CVV expectedMIT sent as a CITsoft decline 1A / 65 in a loopreference passed throughreference missing or wrongcardholder present (CIT)merchant only (MIT)flagging errorAn orphan MIT is not outside SCA scope: to the issuer, it is an unauthenticated transaction.

The link between the initial CIT and the MITs that follow takes the form of a technical reference, sent in every authorization message. The enrollment CIT returns a transaction identifier, called the Transaction ID at Visa and the Trace ID at Mastercard, which the merchant must store. Each subsequent payment references it, along with the MIT type and an entry mode indicating a stored credential. This reference is the only proof of the mandate the issuer receives. Without it, the issuer treats the message as an unauthenticated card-not-present sale.

What a subscription payment carries on the network side
Initial CIT - subscriber enrollment
  entry mode        : e-commerce, with the "first use of a
                      stored credential" indicator
  authentication    : 3-D Secure successful (the mandate is born here)
  amount            : 0.00 for account verification, or the first payment
  response          : approved
  KEEP              : Transaction ID (Visa) / Trace ID (Mastercard)
                      this is the evidence of the card mandate

Recurring MIT - each subsequent payment
  entry mode        : 10 = credential on file
  MIT indicator     : recurring (fixed amount and frequency)
  chained reference : identifier returned by the initial CIT
  CVV2 cryptogram   : absent - storing it is prohibited, so absence is normal
  3-D Secure        : absent - no one is in session

If the chained reference is missing:
  the European issuer sees an unauthenticated card-not-present sale
  -> decline 1A (Visa, CB) or 65 (Mastercard), meaning "authenticate"
  -> no way out: no cardholder is there to authenticate
  -> the payment fails, the retry fails too, and the customer leaves
⚠️
The chain rarely survives a change of provider
The chaining identifier is generated by the network and belongs to it, but in practice it is held by the provider that processed the initial CIT. A poorly prepared PSP migration loses this identifier across the entire subscriber base. The success rate collapses in the first billing cycle after the switch, even though not a single line of checkout code has changed. Portability of network references and tokens must therefore be negotiated before the processing agreement is signed, the only point at which the merchant still has leverage over its provider.
  • The amount changes: a subscription whose price changes leaves the fixed-amount recurring category. The flag must follow, or the payment will be declined.
  • The frequency changes: switching from monthly to annual starts a new series, not a variant of the old one.
  • Usage becomes variable: an automatic top-up triggered by a threshold falls under unscheduled credential on file, never recurring.
  • A retry after a decline is a separate MIT type, the resubmission, which must carry the amount of the original payment.
  • The network token changes form without changing holder: this is what makes automatic credential updates possible without the customer having to act again.

Credential maintenance is a service you sign up for, separate from simply storing the payment method. The schemes run updater services, chiefly Visa Account Updater and its real-time version, and Mastercard's Automatic Billing Updater. Network tokens issued under the EMVCo specification survive card reissuance, because the token stays stable and only its internal mapping changes. A subscription program that stores card numbers in the clear, without using one of these services, loses a share of its base every year as cards expire or are reissued.

What the schemes require of a subscription merchant

The MCC, or merchant category code, is a 4-digit code that classifies a merchant by business type. MCC 5968, Direct Marketing — Continuity/Subscription Merchants, covers merchants that bill on a continuing basis. The code has three distinct effects. It feeds issuer scoring, determines interchange rates, and triggers closer monitoring of dispute rates. A subscription merchant classified under another MCC gets better approval rates in the short term, but loses the category's protection at the first dispute.

Network rules have tightened around one specific case: the free trial that converts to a paid subscription. Visa and Mastercard impose a chain of requirements on this flow. Consent must be collected separately from the purchase, and a reminder must precede the conversion. A receipt must follow each charge. The statement descriptor must identify the merchant clearly enough for the cardholder to recognize it without effort, and cancellation must remain available online, as easily as sign-up.

TimingWhat's requiredWhat to monitor in production
EnrollmentExplicit consent to storing the credential, separate from accepting the terms and conditions; authentication of the initial transactionConsent timestamp, record of the flow, presence of the chaining identifier returned by the network
End of trialReminder sent to the customer before the first paid charge, stating the amount and dateDispute rate within 30 days of conversion, the metric that exposes a missing or unclear reminder
Every paymentReceipt to the customer, recognizable statement descriptor, correct MIT flagShare of authorizations carrying the chained reference; approval rate gap between flagged and unflagged MITs
CancellationOnline cancellation path, debits actually stopped, confirmation to the customerTime between the cancellation request and the actual end of the series; disputes arise in that window
The four moments scheme rules govern

Subscription disputes have their own reason codes. At Visa, condition 13.2 covers a canceled recurring transaction, while Mastercard uses reason code 4841, Cancelled Recurring or Digital Goods Transactions. The merchant's defense rests on three pieces of evidence: proof of the initial consent, proof of the information provided before the charge, and proof that no cancellation had occurred by the billing date. The case is decided on those three items, and no commercial argument makes up for a missing one.

ℹ️
Subscription disputes are won at enrollment
Representment win rates are low in subscription disputes. The evidence almost always fails at the same point in the flow: the moment the customer consented. An application log that records only “box checked,” with no timestamp, IP address, or version of the accepted terms, can't establish either the date or the scope of consent for the issuer. Retaining the enrollment flow is therefore a product design decision, and what it must capture is decided when the sign-up page is built. Once the dispute arrives, nothing can reconstruct evidence that was never recorded.

Bank mandates: what they cost, what they deliver

A direct debit is a debit from an account initiated by the creditor, under a mandate the account holder gave in advance. In most mature markets, recurring bills go through this channel rather than cards. Direct debit costs a fraction of a card authorization, is unaffected by credential expiry, and its success rate depends on a single variable: available funds on the collection date. In exchange, it exposes the creditor to a revocability cards don't have, and it requires bank sponsorship that not every creditor can get.

MarketInstrumentOperatorAdvance notice to payerWhat sets it apart
SEPA areaSEPA Direct Debit Core and B2BEuropean Payments Council (scheme), since 200914 calendar days by default, can be shortened by agreementTwo rulebooks with opposite rights: no-questions-asked refund within 8 weeks under Core, none under B2B
United KingdomDirect Debit via BacsPay.UK, operated by Vocalink (Mastercard), since 196810 business days by default, set in the sponsorship agreementDirect Debit Guarantee with no cap and no time limit; access requires a Service User Number obtained from your bank
United StatesACH debit, SEC codes PPD and WEBNacha (rules), FedACH and EPN (clearing), since 197210 calendar days before any debit in a different amount from the previous oneUnauthorized-debit returns open for 60 calendar days; account validation required on the first WEB debit
SwedenAutogiroBankgirot, since 1969Per the service agreementNever migrated to SEPA: Swedish recurring payments run in kronor on a domestic rail
DenmarkBetalingsserviceMastercard Payment Services, since 1974Built into the system cycleCentrally managed mandates and a fixed monthly cycle: the billing calendar is imposed, not chosen
NorwayAvtaleGiroFinance Norway / Mastercard Payment ServicesNotification by the payer's bankThe payer sees and approves upcoming payments in online banking before they go out
NetherlandsIncassomachtigenCurrence, since 2016SEPA Direct Debit rulesSEPA mandates are signed with bank authentication, the only such system rolled out at national scale
SwitzerlandLSV+ and Debit DirectSIX (LSV+) / PostFinance (Debit Direct)Depends on the procedure usedNon-SEPA procedures: a creditor collecting in Swiss francs integrates them separately from its euro flows
SingaporeGIROBanking Computer Services for the Association of Banks in Singapore, since 1984Set by the billerDominant for recurring bills and taxes, despite a mature local instant payment system
United Arab EmiratesUAEDDSCentral Bank of the UAE, since 2012Per the registered mandateMandates registered with the central bank, designed to replace post-dated checks
Direct debit rails for recurring payments, market by market
35.2B
ACH payments in the US in 2025, payroll and debits combined
Nacha, 2026
5.0B
Direct Debit payments in the UK in 2025
Pay.UK, 2025 annual statistics
117 000
*service users* registered with UK Direct Debit at the end of 2025
Pay.UK
0,5 %
unauthorized return rate above which an ACH originator's bank must step in
Nacha rules
⚠️
Advance notice is not a courtesy
On Bacs as on SEPA, announcing the amount and date before each debit is a scheme requirement. A UK creditor that can't prove it sent the advance notice loses the indemnity claim without any review of the merits. The mechanism is the same everywhere. Advance notice turns a surprise debit into an expected one, and expected debits trigger far fewer disputes, which cuts both the returns to reserve for and the cases to handle.

US ACH differs from every other rail in having no mandate in the European sense. It has no standardized creditor identifier, no reference carried in the message, and no sequence control. The authorization that takes its place varies in form depending on the channel through which it is obtained, and is declared to the network with a three-letter code. The risk sits with the bank that enters the transaction into the network, not with a scheme. A US creditor therefore negotiates its program terms with its bank, which applies its own risk appetite.

The next generation: mandates created in the payer's app

A native mandate is a direct debit authorization created and stored in the payer's banking app rather than in the creditor's records. The model emerged in Asia-Pacific, then in Latin America. The mandate becomes visible to the payer, listed among their active authorizations, and can be suspended or revoked in three taps without going through the creditor. The underlying rail is instant, so collection is too, and the creditor gains a higher success rate and immediate settlement. What it loses is control over when the series stops, since that decision is made in an app it can't see.

2016
e-NACH and Incassomachtigen
India's NPCI (National Payments Corporation of India) opens the NACH rail to electronic mandates signed with Aadhaar (the national digital ID), net banking, or a debit card. In the Netherlands, Currence rolls out SEPA mandate signing via bank authentication at scale.
2017
Stored Credential Framework
Visa requires transactions on stored credentials to be flagged, and Mastercard follows, making the card mandate identifiable in the authorization message itself.
2020
UPI AutoPay
The NPCI adds recurring mandates to India's instant payment rail, where the authorization is tied to the payer's UPI ID and granted in seconds.
2022
PayTo in Australia
NPP Australia puts the mandate in the banking app, with real-time creation, suspension, and revocation. It is designed to replace BECS direct debit.
June 16, 2025
Pix Automático in Brazil
Banco Central do Brasil launches recurring authorization on Pix under Resolução BCB nº 402 of July 22, 2024, and every payer-side participant must offer it.
April 21, 2026
Digital Payments – E-mandate Framework, 2026
The Reserve Bank of India consolidates the e-mandate rules for cards, UPI, and prepaid instruments into a single text, covering both domestic and cross-border payments.
SystemOperatorSinceWhat it means for the creditor
PayToNPP Australia (Australian Payments Plus)2022Mandate created, capped, and revoked in the banking app; instant settlement, with no refund guarantee comparable to direct debit
Pix AutomáticoBanco Central do Brasil2025Payees must be legal entities, payer fees prohibited, frequency set at authorization; no dispute possible after settlement
UPI AutoPayNational Payments Corporation of India2020Enrollment in seconds in the UPI app; immediate rejection on failure, so a same-day retry is possible
e-NACHNational Payments Corporation of India2016Longer enrollment flow, but suited to large amounts: loan repayments, insurance premiums, systematic investment plans
DuitNow AutoDebitPayments Network Malaysia, supervised by Bank Negara Malaysia–The direct debit component of the PayNet lineup: the piece missing from DuitNow Transfer and FPX, both payer-initiated
Variable Recurring PaymentsStandard published by Open Banking Limited (UK)–Capped mandate held in the banking app, on the Faster Payments rail; sweeping is live, commercial VRP not yet at scale
Mandates held on the payer's side: who operates what

Pix Automático is the best-documented system of this generation, since Brazilian regulation sets out its collection mechanics in detail. The payment instruction is sent between two and 10 days before the scheduled settlement date. Settlement itself has two mandatory windows, midnight to 8 a.m. and 6 p.m. to 9 p.m., Brasília time. A failure triggers a new attempt the same day, preceded by a notification asking the payer to add funds to the account. Attempts can continue for up to seven days if the authorization allows it.

🔑
Instant revocation vs. a refund window
The two models trade one risk for another. Classic direct debit lets the money go, then lets the payer claim it back: for eight weeks under SEPA Core and with no time limit in the UK. The native mandate allows no clawback, and a settled payment stays with the creditor. In exchange, the payer can stop the series at any time from their phone, without contacting the creditor or giving notice. A creditor coming from SEPA that applies its usual model here reserves for refunds that won't happen, and leaves the revenue lost to revocation unreserved. The line to watch becomes churn forecasting, not the returns reserve.

Authenticate once, charge a hundred times

Authentication of a recurring series follows a principle shared by every regime. The customer is strongly authenticated once, at enrollment, and subsequent payments run without any further action on their part. Regimes then differ on how far that exemption extends, what amounts it covers, and when it stops applying.

In the European Economic Area, two texts work together. Article 14 of Delegated Regulation (EU) 2018/389 exempts from strong customer authentication recurring transactions of the same amount to the same payee. Authentication applies only to the first payment. Merchant-initiated transactions follow separate reasoning: the European Banking Authority placed them out of scope in its June 2019 opinion, because the payer doesn't initiate them. In both cases the exemption depends on the flag carried in the authorization message, and a missing or wrong flag removes it.

RegionApplicable lawAt enrollmentFor subsequent payments
European Economic AreaDelegated Regulation (EU) 2018/389, Art. 14; European Banking Authority opinion of June 2019 on MITsStrong authentication requiredNone, if the series is flagged and chained correctly
IndiaDigital Payments – E-mandate Framework, 2026, Reserve Bank of IndiaStrong authentication required, no exceptionsNone up to ₹15,000 per transaction; the threshold rises to ₹1 lakh (₹100,000) for insurance premiums, mutual fund subscriptions, and credit card bill payments
BrazilPix Automático, Resolução BCB nº 402 of July 22, 2024Authorization given in the payer's app, through one of the four prescribed flowsNone; the payer can still cancel a scheduled payment
AustraliaPayTo rules, NPP AustraliaMandate created and authenticated in the payer's banking appNone; suspension and revocation remain self-service
United StatesNacha rules; Regulation E (12 CFR 1005)Authorization whose form depends on the SEC code; account validation on the first WEB debitNone; the unauthorized-debit return stays open for 60 calendar days
Authenticating enrollment, then payments: five regimes

The Indian framework moves the point where a series can break, by letting the payer refuse each payment after seeing it announced. Every debit must be preceded by a pre-debit notification sent at least 24 hours in advance, stating the payee's name, the amount, the date and time, the mandate reference, and the purpose. The payer can decline transaction by transaction. Revoking a mandate requires strong authentication, and charging the customer for using the e-mandate service is prohibited.

⚠️
Twenty-four hours' notice changes what the failure rate means
A retry model imported from Europe or the US works from rejection codes. In India, some failures happen the day before the debit, when the payer reads the pre-debit notification and declines the payment. The account has funds and the instrument is valid; the only cause of the failure is the payer's decision. A retry therefore doesn't address the cause, which lies in how clear the notification is and how much the customer values the service when it arrives. For this reason, monitoring an Indian program separates explicit refusals from technical rejections.

The declined payment: read, fix, retry

A failed payment falls into one of two families, depending on whether the payment instrument is still usable. In the first, the instrument no longer exists in the form the creditor has on file, because the card expired, the account was closed, or the mandate was revoked. No re-presentment will succeed. In the second, the instrument is still valid and only the funds were missing at the time of the debit, so a later attempt has a good chance of succeeding. Treating the first family like the second produces pointless retries that the network bills for and sometimes penalizes.

RailCode or fileWhat it meansWhat to do
Card51Insufficient fundsDeferred retry, timed to a payday
Card54Expired cardThe credential is dead: update it through the scheme's service, or get a new card from the customer
Card1A / 65Strong authentication requiredMissing MIT flag: fix the integration, don't replay the payment
Card05Generic issuer declineOne retry, no more; beyond that, you're using up a billed retry budget
SEPAAM04Insufficient fundsRe-presentment allowed within rulebook limits
SEPAMD01No mandate or invalid mandateStop the series and get a new mandate signed; any other action makes the case worse
SEPAMS03Reason not specifiedTreat it as a payer refusal: the bank won't say more, but the customer will
SEPAAC04Account closedNew account details required; never re-present
ACHR01Insufficient fundsNacha allows up to two re-presentments after an R01
ACHR10The account holder reports the debit as unauthorizedSixty calendar days after settlement: the real cost of a US consumer debit
BacsARUDD fileThe cycle's unpaid items, with reason codesIt arrives on settlement day itself: treasury must plan for it, not discover it
BacsADDACS fileThe payer has canceled their instructionThe customer is gone. Cut off the service and stop the series before calling
Reading a failed payment, rail by rail
Recurring payment failureread the code BEFORE retryingInsufficient fundscodes 51 · 61retry D+2 / D+5 / D+9Technical declinecodes 91 · 96 · timeoutretry within 1 hourExpired cardcode 54 · reissueaccount updater + tokenHard declinecodes 04 · 41 · 43 · MAC 03MAC 03 = stop tryingCode-driven retryspaced-out windows + advance notice to the customerStop and contact the customeremail, another payment methodBlind retries damage the MIDsystemic declines, attempts counted and billed by the schemesdelayed retryfix the cardstop retryingRetrying a hard decline isn't a retry strategy: the schemes count it as another attempt.
The retry cycle for a declined payment
D0, decline
Classify the code, don't just count it
Dead instrument or insufficient funds: the path splits here and determines everything that follows
D0, repair
Update the credential before any retry
Query the scheme's updater service, use a network token, or ask for new bank details
D0, pre-retry notice
Notify the customer before retrying
A message announcing the new attempt and its date converts better than a silent retry
D+2 to D+7, retry
Retry in a chosen window, flagged as a resubmission
The local payday calendar matters more than the theoretical interval
D+7 to D+21, escalation
Switch instruments rather than keep trying
Offering another payment method recovers more than a fifth attempt on the same credential
End
Suspend the service, then close the series
A series left open on a dead instrument generates attempt fees and disputes

The networks cap retries. Visa limits new attempts on a declined transaction to 15 in 30 days, with fees beyond that, and Mastercard runs a comparable program to monitor excessive retries. Some declines are final, such as a stolen card, an invalid number, or suspected fraud, and retrying them exposes the merchant to acquirer penalties. A merchant's retry policy therefore operates within a limit set by the scheme, and going over it costs attempt fees and penalties.

🔑
Report two rates, not one
The success rate “after retries” is the figure most often reported, and it combines two separate effects. An aggressive retry policy pushes it up, at the cost of a spent retry budget and future disputes. The second figure is the first-attempt rate, measured before any re-presentment. The gap between the two isolates what retries actually contribute, separately from the quality of the instruments on file and the timeliness of funds. It lets you weigh the gain against the cost of extra attempts, and find the point beyond which one more attempt costs more than it brings in.

Cancellation: what the law requires, market by market

Canceling a subscription is how the customer ends the contract and, in principle, the debits that come with it. Several markets now require cancellation to be as easy as sign-up, and available through the same channel. The laws agree on the principle and differ on the details, since each prescribes a different flow, with its own wording, deadlines, and evidence. Cancellation handling moves from customer service to compliance, then to online flow engineering.

MarketLegal basisWhat it requiresImpact on payments
Germany§ 312k BGB, the Kündigungsbutton (cancellation button)A button labeled “Verträge hier kündigen” (cancel contracts here), clearly legible and always accessible, then a confirmation page with “jetzt kündigen” (cancel now)Cancellation becomes a timestamped, legally binding product event, rather than an exchange of emails
CaliforniaAutomatic Renewal Law, as amended by AB 2863Cancellation through the sign-up channel, a direct online link or button, an annual reminder, 7 to 30 days' notice before any price changeApplies to contracts entered into, amended, or renewed on or after July 1, 2025
US (federal)Restore Online Shoppers' Confidence Act, 15 U.S.C. § 8403Clear disclosure before the charge, express consent, a simple mechanism to stop recurring chargesThe FTC's click-to-cancel rule was vacated by the Eighth Circuit Court of Appeals in July 2025; ROSCA remains the basis for enforcement
European UnionDirective 2011/83/EU on consumer rights14-day withdrawal period for distance contractsThe right applies to the contract, not the payment mandate: the mandate must be canceled separately
IndiaDigital Payments – E-mandate Framework, 2026Pre-debit notification 24 hours before each debit, the right to decline transaction by transaction, mandate revocation with strong authenticationSome churn is triggered the day before the debit, not at renewal
BrazilPix Automático, Resolução BCB nº 402Immediate revocation from the payer's app, which also ends the recurrenceNo refund window: the mandate dies, and payments already settled stay with the creditor
AustraliaPayTo rules, NPP AustraliaReal-time mandate suspension and revocation in the banking appThe creditor finds out at the next rejection, never before
United KingdomDirect Debit Guarantee, Pay.UKImmediate, full refund of an erroneous direct debit by the payer's bankNo cap and no time limit; the bank then recovers the amount from the creditor through an indemnity claim
Subscription exit requirements and how they affect collection

These requirements share two features. The first is their subject: recent laws regulate the cancellation flow, not the contract's content, by requiring a button, a confirmation page, and a deadline for it to take effect. The second is the gap between the legal act and its technical execution. Canceling a contract never automatically ends a payment mandate, and ending the mandate doesn't cancel the contract. A customer can have canceled properly and still be debited, just as they can have blocked their mandate without ever canceling.

⚠️
Design the exit flow once, for every market
Building a separate cancellation flow for each jurisdiction multiplies the variants to maintain, test, and rework every time the rules change, and the system becomes unmanageable by the third country. The approach that works is to implement the most demanding regime everywhere, then add only the mandatory local wording. German law prescribes its wording word for word, and adding it to an already compliant flow costs little. A flow left noncompliant in a secondary market, on the other hand, exposes you to lawsuits, fines, and lost subscription disputes.

Running a multi-market subscription program

An international subscription program rarely fails because of its product, and almost always because of its payment collection mechanics, market by market and at the same points. Opening a country therefore means revisiting four collection decisions that are independent of the product sold: the choice of instruments, the quality of recurring-series flagging, separate measurement of the two kinds of churn, and how to set reserves.

🧾
The instrument mix
Cards are rarely enough. For recurring bills, direct debit dominates in the UK, the Nordics, Singapore, and the UAE. In India, the choice is between e-NACH for large amounts and UPI AutoPay for the mass market.
🔗
The flagging chain
Audit the share of recurring authorizations carrying the chained reference, by market and by provider. An approval rate gap between flagged and unflagged series immediately puts a number on the integration defect.
📉
Separating the two kinds of churn
Track voluntary churn and involuntary failures separately. The first is a product and pricing issue. The second comes down to credential maintenance, the retry schedule, and the quality of advance notices.
⚖️
Reserves by regime
Reserve by instrument, never by revenue. Eight weeks under SEPA Core, no time limit in the UK, 60 days on consumer ACH, nothing on Pix Automático.
  • Check the portability of tokens and network references in every provider contract before signing, the only time you have leverage.
  • Classify your MCC honestly: a subscription merchant filed under another code loses its category's protection at the first dispute.
  • Archive the enrollment flow with timestamp, IP address, and version of the accepted terms: it is the missing piece in nine out of ten dispute cases.
  • Send advance notice wherever it is required, and keep a record. On Bacs, failing to send it means losing the indemnity claim without review.
  • Set a retry policy by code, with an attempt cap below the scheme's, and stop immediately on final declines.
  • Measure the first-attempt rate alongside the post-retry rate, by market, instrument, and provider.
  • Build a single online cancellation flow, aligned with the most demanding regime, plus the mandatory local wording.
  • Document how mandates end in both directions: contract cancellation that stops the series, and mandate revocation that cuts off the service.
🔑
The question to ask before entering a market
It comes down to who can stop the payments and how long it takes the creditor to find out. With cards, stopping the series goes through the merchant, but the credential can stop working without anyone deciding anything. Under SEPA, the payer's bank stops the series and refunds up to eight weeks back, while in the UK it refunds with no time limit. On PayTo and Pix Automático, the customer stops the series themselves in three seconds, and the creditor finds out at the next rejection. The recurring revenue model is the same from one market to the next, but how it breaks changes with the instrument.